Privacy & Cookies
Personal Data Processing and Cookie Policy
This Personal Data Processing and Cookie Policy (hereinafter — the “Policy”) establishes the procedure for the collection, storage, processing and transfer of the Personal Data of Users of the Platform of Changebox Limited, registered in the British Virgin Islands, registration number 2171550 (hereinafter — the “Operator” or “we”). It also discloses information about the measures taken by the Operator to ensure the security of Personal Data, aimed at protecting the rights and freedoms of Users, including the right to privacy and to personal, family and commercial secrecy.
The Policy is part of the ChangeBox Platform Terms of Use and their annexes. Please read this Policy carefully. If you have any questions or doubts, please contact us via the Platform or by sending an email to: legal@changebox.io.
1. Terms and definitions
1.1. The following terms are used in this document:
1.2. Terms and definitions used in the Policy but not defined above are understood in the meaning given to them by the General Terms and their annexes, and in the absence of a definition therein — in accordance with the interpretations presented on the Internet.
2. Procedure for expressing agreement with the terms
2.1. If you agree with the provisions of this Policy, you may accept them by placing a “☑” mark or its equivalent next to the field “I agree with the terms of the Personal Data Processing and Cookie Policy” when registering an Account or visiting the Platform.
2.2. If, at any time, you do not agree with any provision of this Policy, you must immediately stop using the Platform and the Services.
3. Personal Data collected
3.1. In order to provide access to the Platform, we request information about yourself from Users; such data can be divided into the following categories:
3.2. We are constantly developing the Platform and the Services by adding new functions and features. In this regard, the table of collected Personal Data specified above may change. To access new functions, we may request that you provide additional information about yourself. In doing so, we will be sure to notify you of such changes and request your consent to the collection and Processing of additional Personal Data.
3.3. Please note that the provision of Personal Data is entirely voluntary. However, a refusal to provide data may restrict your access to certain Services and functional features of the Platform, especially to those that require completing the Account verification procedure.
4. Purposes of collecting and processing Personal Data
4.1. We collect your Personal Data for the following purposes:
4.2. We undertake to use your Personal Data exclusively for the above purposes. Exceptions are cases where the collection and use of data are required for other purposes compatible with the original purpose, or where this is necessary in accordance with applicable laws, court acts or orders of executive authorities.
4.3. If we need to use your Personal Data for purposes other than those specified above, we will notify you in advance and provide information about the legal grounds for such use.
5. Procedure for collecting Personal Data
5.1. We may collect Users' Personal Data in various ways:
6. Personal Data retention period
6.1. We store your Personal Data only for the time necessary to achieve the purposes of their collection and processing, or within the periods established by applicable legislation. Depending on the category of Personal Data, the following applicable retention periods can be distinguished:
6.2. Please note that we may store your Personal Data for a longer period if this is necessary to comply with the requirements of applicable laws and regulations. Some Personal Data may be retained even after your Account is closed for the purposes of preventing fraud, ensuring the possibility of prosecuting persons involved in fraudulent actions, and complying with our legal obligations.
7. Legal grounds for processing Personal Data
7.1. The processing of Personal Data is carried out in accordance with the Regulation of the European Parliament and of the Council of the European Union on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (the “General Data Protection Regulation” or “GDPR”) and our local rules.
7.2. In cases where the legislation of your country of location establishes stricter standards for the processing of Personal Data, we undertake to comply with such standards when processing your data.
7.3. The legal grounds for processing Personal Data include the following:
- Consent. The processing of personal data may be carried out with your prior explicit consent, given voluntarily, on an informed basis and unambiguously. You have the right to withdraw your consent at any time by notifying us of this, which will lead to the cessation of the processing of your Personal Data if it was based solely on this ground. The withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal of consent.
- Performance of a contract. We process your personal data within the framework of performing obligations under a contract to which you are a party, or to take the necessary measures before its conclusion. The processing may include User identification and the provision of access to the Services.
- Legitimate interests. We may process your personal data to protect our legitimate interests or the interests of third parties, provided that such interests do not infringe your rights, freedoms and legitimate interests. Legitimate interests may include ensuring the security of the Platform, preventing fraud, and improving the quality of the Services.
- Compliance with legislation. We are obliged to process personal data in cases where this is necessary to fulfill the obligations established by the legislative and regulatory acts of the British Virgin Islands. This may include compliance with legislative requirements in the field of providing services in respect of Virtual Assets, taxation, accounting, financial control or consumer protection, as well as obligations to provide data to state authorities in cases provided for by law.
8. Transfer of your Personal Data to third parties
8.1. We transfer your Personal Data to third parties exclusively to the extent necessary to achieve the processing purposes specified in this Policy, and in accordance with the applicable legislation of the British Virgin Islands.
8.2. The transfer is carried out only in the following cases:
- with your prior explicit consent to this;
- within the framework of performing a contract to which you are a party;
- to fulfill our legal obligations;
- to protect our legitimate interests or the interests of third parties.
8.3. Your Personal Data may be transferred to the following categories of persons:
- Business partners, suppliers and subcontractors: we may engage external service providers, such as Agents, Counterparties, payment providers, notification delivery services and other companies that help us provide the Services and ensure the operation of the Platform.
- Legal and state authorities: your Personal Data may be transferred to the competent state authorities, including judicial bodies and law enforcement authorities.
- Legal successors: in the event of a reorganization, merger, sale or other transfer of our business, your Personal Data may be transferred to the legal successor, subject to compliance with confidentiality and the use of the data in accordance with this Policy.
8.4. We guarantee to you that we will not sell, exchange or transfer your Personal Data to third parties without your explicit consent to this.
8.5. We take all necessary measures to protect your Personal Data during its transfer to third parties, including the use of confidentiality agreements, encryption mechanisms and other technical and organizational means.
8.6. We are not responsible for the use of your Personal Data by third parties if such transfer was carried out on the basis of your consent or in cases provided for by legislation.
8.7. You have the right to request information about to whom, when and on what grounds your Personal Data was transferred by contacting us via the contact details specified in this Policy.
9. Cross-border transfer of Personal Data
9.1. To ensure the possibility of providing the Services and operating the Platform, we may use the services of foreign data processing service providers where permitted by the law applicable to the Processing of your Personal Data. In addition, certain jurisdictions establish requirements to store Personal Data on servers located within the territory of the state of the Personal Data subject.
9.2. In the event of the transfer of your Personal Data outside the British Virgin Islands, we ensure compliance with all requirements of applicable legislation, including:
- ensuring an adequate level of data protection in the recipient's country;
- concluding agreements with data recipients that contain provisions on the protection of personal data;
- obtaining your consent if required by legislation.
9.3. We recognize the importance of protecting your Personal Data when it is transferred outside the British Virgin Islands. In the event that your Personal Data is transferred to other countries, we ensure compliance with the requirements of data protection legislation, including, but not limited to, the GDPR, depending on the jurisdiction.
9.4. To ensure the security of your Personal Data during cross-border transfer, we take the following measures:
- Enshrining standards for handling Personal Data in the contract. We conclude contracts with third parties to whom we transfer your Personal Data, in which we stipulate requirements for interaction with Users' Personal Data intended to ensure a sufficient level of protection of Personal Data.
- Analysis of the level of data protection. We assess the level of data protection in the countries to which data may be transferred and take additional protective measures if necessary.
- Use of encryption technologies. We apply protective means, such as encryption, to ensure the confidentiality and security of your data when it is transferred through international channels.
10. Applied measures for protecting Personal Data
10.1. We have implemented a comprehensive approach to ensure the confidentiality, integrity and security of your Personal Data, taking measures to prevent its loss, theft, unauthorized access, misuse, alteration or destruction. These measures include both technical and organizational security measures that comply with the best global data protection practices.
10.2. To ensure the security of your data, we use modern encryption technologies and other protection methods. The main technical measures include:
- Data encryption: we apply the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols, which ensure the secure transmission of data over the Internet, guaranteeing its encryption and protection from interception. All data transmitted between you and our platform is protected using these technologies, which prevents the possibility of it being read or modified by third parties.
- HTTPS and secure coding: we ensure data protection using HTTPS and secure coding, which helps prevent information leakage during its transmission over the network.
- Regular security checks: we regularly conduct penetration testing and assess the vulnerabilities of our security system to minimize risks associated with data security.
10.3. We also take the following organizational measures to protect your Personal Data:
- Access restriction: only a limited circle of authorized employees has access to your Personal Data, and this access is strictly controlled. All employees are obliged to maintain confidentiality and not to transfer information to third parties without legal grounds to do so.
- Security policies and procedures: we have implemented strict internal security policies and procedures to guarantee the proper protection of data and its processing in accordance with applicable laws and regulations.
- Employee training: our employees undergo regular training on confidentiality and data protection to ensure that all operations with Personal Data comply with current requirements and security standards.
10.4. Periodically, we assess and update security measures taking into account changes in legislation, technologies and threats. This allows us to respond promptly to potential risks and improve the protection of your Personal Data.
10.5. We use modern systems for protection against external threats, such as firewalls and antivirus programs, to prevent unauthorized access and minimize the risks of exposure to external attacks.
11. Rights of Users as Personal Data subjects
11.1. Your main rights as a personal data subject include the following:
- Right of access: you have the right to request information about what Personal Data about you is being processed, as well as to obtain a copy of this data. We provide you with information about the fact of the Processing of Personal Data, the legal grounds and purposes of the Processing, the methods of Processing, the sources of obtaining the data, the periods of Processing, the name and location of the holder of the Personal Data array, information about the persons who have access to Personal Data or to whom Personal Data may be transferred, and other information upon your written request. We may request a document confirming your identity before transferring the requested information and may require payment if such information is provided on physical media. The information is provided within a period not exceeding 7 (seven) days from the moment the application is submitted.
- Right to rectification: if your Personal Data is inaccurate or incomplete, you have the right to request its correction. We undertake to update the data within a reasonable time. In doing so, we may request documentary confirmation of the inconsistency of the Personal Data we hold with reality.
- Right to erasure (right to be forgotten): you have the right to request the erasure of your Personal Data if it is no longer required for the purposes for which it was previously requested, if you have withdrawn your consent, if the data was processed unlawfully, or if this is required in accordance with applicable laws. However, in some cases, for example, to fulfill legal obligations, we may be obliged to refuse you and continue to store your Personal Data.
- Right to data portability: you have the right to receive your Personal Data in a structured, commonly used and machine-readable format, as well as to transfer it to another operator, if the processing is based on your consent or a contract and is carried out using automated means.
- Withdrawal of consent: if the processing of your Personal Data is based on your consent, you have the right to withdraw it at any time. The withdrawal of consent does not affect the lawfulness of the data processing carried out before the moment of withdrawal. Any Personal Data whose processing ground differs from your consent will continue to be Processed.
- Right to restriction of Processing: in some jurisdictions, applicable legislation may grant you the right to restrict or object to our Processing or transfer of your Personal Data under certain circumstances. We may continue to Process Personal Data if this is necessary to protect our rights or in any other cases provided for by applicable legislation.
11.2. Please note that none of the above rights is absolute, which means that they generally must be balanced against our own legal obligations and legitimate interests. If a decision is made to reject your request, we will inform you of this along with the reasons for our decision.
11.3. In order to exercise any of the listed rights, please contact us via the contact details specified in this Policy.
11.4. If you believe that your rights to the protection of Personal Data have been violated, you have the right to file a complaint with the competent authority that supervises the processing of personal data in the British Virgin Islands.
12. Links to third-party resources
12.1. The Platform may contain links to external websites and platforms that are owned and operated by third parties. The Personal Data processing policies and practices of these third-party resources may differ from ours, and we do not control their content or the procedure for processing data.
12.2. The Operator is not responsible for the protection of Personal Data or the confidentiality measures applied by such third parties. We recommend that you carefully read the privacy policies of each third-party resource before using their services, providing Personal Data or any other information.
12.3. The use of links to third-party resources is carried out by the User at their own risk. The Operator does not guarantee the availability, security or reliability of such third-party resources and is not responsible for possible losses caused as a result of their use.
13. Cookies
13.1. A Cookie is a small text file that is stored on your device when you visit the Platform. Certain information is stored in this text file, for example, the choice of language. When you visit the site again, this Cookie is sent to the site, which recognizes your browser and can display the corresponding language version of the text on the site.
13.2. The Operator uses Cookies and similar technologies to improve the functionality of the Platform, analyze the user experience, monitor the use of the Platform's functional features and provide personalized content and advertising.
13.3. On your first visit to the Platform, we request your consent to place Cookies on your device.
13.4. You can manage Cookies through your browser settings. You have the right to prohibit the use of Cookies, however this may limit the functionality of the Platform. To learn more about Cookies, including finding out which Cookies have been set, visit www.aboutcookies.org or www.allaboutcookies.org.
13.5. You can prohibit your browser from accepting certain Cookies, require your browser to obtain your consent before a new Cookie is placed in your browser, or completely block Cookies by selecting the appropriate settings in the privacy settings menu of your browser. To find information relating to specific browsers, visit the browser developer's website.
14. Amendments to the Policy
14.1. The Operator hereby reserves the right, at its discretion and at any time, to make changes to this Policy by publishing its amended version on the Platform. The new version of the Policy will include the amended date of the last update on its first page.
14.2. The User undertakes, at their own risk, to constantly check for changes to the Policy and to perform the following actions: (i) remember/note the date of the last update specified in the Policy (for example, keep a copy of the Policy, etc.) at the initial registration of their Account and at any time after changes are made, (ii) regularly visit the relevant page of the Platform and study the document in the event of a change in the update date.
14.3. In the event that you do not agree with any changes to the Policy, you must immediately stop using the Platform and the Services.
15. Our contact details
15.1. If anything remains unclear in the text of this Policy, we will be happy to clarify its provisions. You may also use the contact details specified in this section for any reason provided for by this Policy.
15.2. For questions related to this Policy, please contact us by email at: legal@changebox.io.